zx41r/awesome-reverse-engineering-and-malware-analysis — explained in plain English
Analysis updated 2026-05-18
Follow a guided track to learn Windows malware analysis from scratch.
Find verified, up to date tools for static and dynamic binary analysis.
Look up researcher blogs and writeups on specific reverse engineering topics.
Discover DFIR and threat intelligence resources organized by topic.
| zx41r/awesome-reverse-engineering-and-malware-analysis | byjoey/xray-cf-lite | code-leafy/g2rayxcodeleafy | |
|---|---|---|---|
| Stars | 59 | 58 | 60 |
| Language | Shell | Shell | Shell |
| Setup difficulty | easy | moderate | moderate |
| Complexity | 1/5 | 3/5 | 3/5 |
| Audience | researcher | ops devops | developer |
Figures from each repo's GitHub metadata at analysis time.
This repository, nicknamed unpacked, is a curated list of resources for reverse engineering and malware analysis. Its main selling point is quality control: every linked resource has actually been opened and checked before being added, and it gets removed the moment it goes dead or stale, instead of accumulating one word notes or vague filler entries the way many similar lists do. The list covers a wide range of topics: static and dynamic analysis, unpacking, exploit development, fuzzing, firmware and embedded systems, mobile platforms, operating system internals, digital forensics and incident response, and threat intelligence, along with researcher blogs and standalone writeups that larger lists tend to miss. Each entry is tagged with its difficulty level, its type such as tool, blog, writeup, course, video, paper, or book, and any relevant notes like whether it requires payment or signup, or if it is written in a language other than English. For newcomers, the README suggests specific guided tracks rather than reading the whole list top to bottom, such as a path through Windows malware analysis, Linux and ELF reversing, exploit development, firmware and embedded work, mobile app internals, or anti-analysis techniques like obfuscation and anti-debugging. The full topic map is organized into folders covering foundations, reverse engineering tools, malware analysis, malware development for study purposes, exploit development, fuzzing, firmware, mobile, operating system internals, anti-analysis, living off the land techniques, DFIR, threat intelligence, and learning platforms like CTFs. The README also lists several community forums where reverse engineers post first, including some Chinese language communities alongside English ones like Reddit's reverse engineering and malware subreddits. The project is released under CC0 1.0, meaning it is dedicated to the public domain with no restrictions.
A carefully curated and continuously verified list of reverse engineering and malware analysis resources, organized into guided learning tracks.
Mainly Shell. The stack also includes Shell, Markdown.
Released under CC0 1.0, meaning it is dedicated to the public domain and can be used for any purpose with no restrictions.
Setup difficulty is rated easy, with roughly 5min to a first successful run.
Mainly researcher.
This repo across BitVibe Labs
Don't trust strangers blindly. Verify against the repo.